Skip to main content
NG Technologies

Published by NG Technologies

Remote Trust PKI

Public key infrastructure

Your own certification authority, built first to issue signature certificates on an HSM, with delegated registration authorities (AED) close to the applicants. Natively integrated with NGSIGN and QRSecure. The infrastructure stays on your territory.

Features

  • Offline root authority and intermediate authorities, two-level hierarchy
  • Registration authority and delegated registration authorities (AED): ministries, banks, operators
  • Identification set by the certificate policy: face-to-face, through an AED or by video identification
  • Full certificate lifecycle: enrolment, issuance, renewal and revocation
  • CRL and ARL publication, OCSP responder
  • Timestamping authority (TSA and TSU units)
  • Certificate profiles: signature and seal
  • Native integration with NGSIGN and QRSecure: issued certificates sign and stamp with no wiring
  • Multi-entity management with fine-grained role delegation
  • Standard HSM interface: FIPS 140-2 level 3 or Common Criteria EAL4+, no proprietary calls

Components

  • ServerRemote Trust CA
  • ServerRemote Trust RA
  • ServerRemote Trust KMS
  • PlatformRemote Trust AED
  • PlatformRemote Trust Admin Portal
  • APIRemote Trust API
  • ApplicationConnecteurs NGSIGN et QRSecure

Key usage

The same product, according to what you need to prove.

  • Signature certificates on an HSM

    The core of Remote Trust: qualified signature certificates whose key is born and stays in the HSM, activated remotely by the signer from NGSIGN.

  • Delegated registration authorities

    Ministries, banks and operators enrol their own applicants at the counter, under the central authority’s policy, with Remote Trust AED.

  • Encryption keys for public procurement

    Bids are encrypted by the bidders and opened on the set date: Remote Trust KMS issues and keeps the encryption keys of the opening committees.

  • National PKI

    Root and intermediate authorities operated in your name, on your territory, with the evidentiary weight the country’s law grants.

  • Enterprise PKI

    An internal authority for your people, your applications and your devices, kept separate from public trust.

  • Seal certificates for QRSecure

    Certificates for legal entities on a network HSM, used by server sealing and the visible electronic stamp.

  • Key ceremony and audit

    Ceremony conducted and documented before the secret holders, immutable logging: the record your auditor will ask for.

Let’s talk about your authority before we talk about licences.

Tell us who issues certificates today, to whom, and what the regulation requires. We’ll tell you which hierarchy and which delegated authorities you need, including if it turns out to be fewer than you thought.